Cross Realm Not working for SSH

View: New views
2 Messages — Rating Filter:   Alert me  

Cross Realm Not working for SSH

by Abhishek Chowdhury :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

hi
i am using kerberos V5 and MAC OS X 10.5.2

i have configured 2 realms and established cross realm trust between them.

i have to use SSH service.

When i am doing SSH in simple authentication, it is working fine ie not asking any password.
but password is being asked for Cross realm.

suppose UserA is in REALMA and SSH server serverB in REALMB

ServerB has an account for UserB(UserB is its admin)

when i do kinit  UserA@REALMA, i get the initial ticket krbtgt/REALMA@REALMA.
now when i am doing ssh UserB@serverB.com it is asking for password.

According to my understanding USERA should be allowed to  access USERB's account on SERVERB for passwrodless ssh.
How to set USERA's access in serverB?
or is there any other method?

any pointers will be appreciated.



Re: Cross Realm Not working for SSH

by Douglas E. Engert :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

UserB needs a ~.k5login file with
UserA@RealmA

Abhishek Chowdhury wrote:

> hi
> i am using kerberos V5 and MAC OS X 10.5.2
>
> i have configured 2 realms and established cross realm trust between them.
>
> i have to use SSH service.
>
> When i am doing SSH in simple authentication, it is working fine ie not
> asking any password.
> but password is being asked for Cross realm.
>
> suppose UserA is in REALMA and SSH server serverB in REALMB
>
> ServerB has an account for UserB(UserB is its admin)
>
> when i do kinit  UserA@REALMA, i get the initial ticket
> krbtgt/REALMA@REALMA.
> now when i am doing ssh UserB@... it is asking for password.
>
> According to my understanding USERA should be allowed to  access USERB's
> account on SERVERB for passwrodless ssh.
> How to set USERA's access in serverB?
> or is there any other method?
>
> any pointers will be appreciated.
>
>
>

--

  Douglas E. Engert  <DEEngert@...>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444
________________________________________________
Kerberos mailing list           Kerberos@...
https://mailman.mit.edu/mailman/listinfo/kerberos